About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Environmental, Social and Governance Services ERP & Enterprise Software Advisory Fraud & Forensics SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Insights & Events

At RubinBrown, we provide valuable insights detailing emerging trends and industry-specific information. Our events, hosted virtually and in-person, keep you informed and connected to the topics and industries that matter most to you and your organization.

View All Insights & Events
Jun 11

RubinBrown’s Leveraging Technology for Business Success

Learn More & Register
Jun 17

RubinBrown’s Rural Health Webinar Series

Learn More & Register

RubinBrown Sports Betting Index: March 2025 Analysis

Learn More

Tax Bill Watch 2025: Budget Resolution Compromise

Learn More

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to Insights

Understanding the Changes in PCI DSS v4.0.1: Key Updates You Need to Know

Contact Us

Understanding the Changes in PCI DSS v4.0.1: Key Updates You Need to Know

Contact Us

Are you impacted by the PCI DSS v4.0.1 updates? 

The changes are minor, but need to be reviewed regardless of merchant or service provider level.

The new Payment Card Industry Data Security Standards (PCI DSS) v4.0 has been effective since March 31, 2024, with minor updates issued in PCI DSS v4.0.1 that was published on June 11, 2024. The update is designed to improve security for payment card transactions, safeguarding sensitive information, maintaining trust in electronic payment systems, and reducing the likelihood of a data breach. The new technical security requirements in v4.0 are currently recommended as a best practice for now and not required to be in place until March 31, 2025. Note that the latest revision v4.0.1 has no additional or deleted requirements. PCI DSS v4.0 will be retired on December 31, 2024, and at that point forward, the only active version supported by the PCI Security Standards Council (PCI SSC) will be v4.0.1. 

We have previously provided Insight articles intended to assist in your understanding of the changes, the timelines, and their effects on PCI compliance. As we have now passed the effective date for the requirements, we will summarize these changes for you and encourage you to communicate and carefully coordinate with your Qualified Security Assessor (QSA). It is important to communicate regularly with your QSA to ensure updates and changes to your overall security posture including administrative, technical, and physical security controls are implemented accordingly to meet the PCI requirements. 

Clarification of the more significant changes with PCI DSS v4.0.1

The new customized approach versus the defined approach to compliance with PCI DSS v4.0.1

The customized approach allows flexibility for the entity by being able to select which PCI requirements the entity desires to customize and requires additional documentation and a risk analysis for each customized approach. It should be noted that compensating controls are not allowed for achieving PCI requirements using the customized approach.

Evolving Requirements Enhancing Security Standards

Evolving requirements make up of several changes that require additional and/or enhanced security protections, including defining the roles and responsibilities of the entity’s user accounts, additional encryption requirements, implementing an automated technical solution (web application firewall (WAF)) for public-facing web applications, management of all payment page scripts that are loaded and executed in the consumer’s browser, implementing multi-factor authentication for all access into the CDE, automating the audit log review process, monitoring failures in critical security controls, and authenticated internal vulnerability scanning. 

Report on Compliance (ROC) template updates

Changes to the ROC template include scope exclusions, self-assessment questionnaires (SAQ) eligibility requirements, storage of SAD, managing third-party service providers, an in-scope component table, sample sets, internal vulnerability scans, and evidence tables. 

Requirements that went into effect for all assessments beginning March 31, 2024 include documenting and assigning roles and responsibilities within each respective requirement, the requirement to document and confirm annually the scope of PCI compliance, and the requirement for performing the target risk analysis for each requirement met with the customized approach. 

These additional requirements also change the SAQs. To comply with the updated standards, a thorough understanding of the scope of the environment and new requirements is necessary. The new customized approach is not allowable for SAQs. 

Feedback and Questions

If you have any inquiries regarding the content of this article or seek guidance on assessing your organization's credit card compliance, please don't hesitate to reach out to RubinBrown. We're here to provide assistance and support in navigating the intricacies of PCI DSS compliance.

 
 

Published: 09/17/2024

Readers should not act upon information presented without individual professional consultation.

Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.

 

Contact Us:

Talk to Our Experts

Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications
1-800-678-3134 Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

Firm News Disclaimers Privacy Policy Client Payment © 2025 RubinBrown LLP
RubinBrown Executive Recruiting RubinBrown Advisors RubinBrown Corporate Finance